The package includes a substantial README, tests, and release notes, with no install-time scripts. Its dependency set is fairly broad, and the project has no security policy.
58%
Total Score
75
50
71
50
Ten runtime dependencies create a relatively broad dependency surface for a young deployment and task-scheduling tool. The available data does not show that these dependencies are problematic, so this is a moderate maintenance concern rather than a severe risk.
No license is declared, no license file is included in the package, and no repository license file was found. This leaves the release without clear legal terms for adoption.
The package is only 94 days old and has three releases, all within roughly five days, so it shows early activity but limited evidence of long-term maintenance.
One contributor made all 45 commits in the last three months, leaving maintenance highly dependent on a single person and increasing abandonment risk.
Composer is used for builds, but no security-scanning tools were detected. The missing scanning is a hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
leafo/scssphp Version ^0.7.5 | — | — |
league/flysystem Version ^3.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
league/flysystem-ftp Version ^3.0 | — | — |
league/flysystem-sftp-v3 Version ^3.33 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.